2lambda123 / rabbitstack-fibratus

Other
0 stars 0 forks source link

Fibratus

Fibratus

A modern tool for Windows kernel exploration and observability with a focus on security
Get Started »

Docs   •   Filaments   •   Download   •   Discussions

What is Fibratus?

Fibratus is a tool for exploration and tracing of the Windows kernel. It lets you trap system-wide events such as process life-cycle, file system I/O, registry modifications or network requests among many other observability signals. In a nutshell, Fibratus allows for gaining deep operational visibility into the Windows kernel but also processes running on top of it. It requires no drivers nor third-party software.

Events can be shipped to a wide array of output sinks or dumped to capture files for local inspection and forensics analysis. The powerful filtering engine permits drilling into the event flux entrails and the rules engine is capable of detecting stealthy adversary attacks and sophisticated threats.

You can use filaments to extend Fibratus with your own arsenal of tools and so leverage the power of the Python ecosystem

Quick start

Check the walkthrough on how to load and create detection rules.

fibratus run file.operation = 'create' and file.name icontains '\\Content.Outlook\\'
fibratus run kevt.name = 'CreateThread' and kevt.pid != thread.pid
fibratus capture kevt.category = 'net' -o conns.kcap
fibratus replay net.dport in (443, 80) -k conns.kcap
fibratus run -f watch_files

Features

Documentation


Setup

Events

Filters and Rules

Captures

Filaments

Outputs

Transformers

Alerts

PE (Portable Executable)

YARA

Troubleshooting


Developed with ❤️ by Nedim Šabić Šabić

Logo designed with ❤️ by Karina Slizova